Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.3-debian-fips-dev, 19.3-debian13-fips-dev, 19.3-fips-dev, 19.3.1-debian-fips-dev, 19.3.1-debian13-fips-dev, 19.3.1-fips-dev

Index digest:

sha256:eb8b93a7617802b8c6bd5b2f97fe78d9cc7f6d7b2f30b4931383247c727f1e17

Manifest digest:

sha256:0734fbde9555a270c5ac49625c86abc1b324e591e75454a5e76a579141e34a48

Size

91.81 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
11
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:16e56135cdde343c8e560283579c0a3be4c926e2f5a3c9c8d09628be5b9b1c8c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:b9484637ea820fc3e10c1f7148f883fe06549e8840bd7a996cb8ea50781bde72
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:eb6db6f315fffbede04a190ca4556ddbfad8390c759af606a9ec8ad84986f58c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:d7dcb4aa98ee1a0deff286d47b3a129f0b5ccc57c11e87c80d310bea09e14855
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:f834521e38306657adafb300a6030900ca03a7a5edc4fd7cb4635abe7dac817e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:3405ac28e51c0d35a8a071dbd8220c614813ebef578acb1a19cf89f0ff49ea85
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:9263b63183523dd0bddee6cd94b4b8a3674c12fe2854e078c6e20824bb5c7c30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:0f1d4092059da3e08cfb71aa656aea8e6fbc2260eee2a2d9bb58e91a76d151bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:ca71c1e85045c5b8e4036ad8d846e33a2a1e484973581879479c4077c2709190
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:9023695be520ccaf06b8bea12cf906654a19f3e3d6779cc2ad356c673cb2272b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:295c2ec0fa0174ef5d31db86a747c3927448df1725c2214f7d7a32ce81c29315
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:0807d030d474dcfc7478f793fec8dd112d935dc08fda0f14978efd0c0db5523d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:e6d3fa6268d6213e077b3eb23033fc0d55a2d49d52a19c58a9e2584c86f5ed7f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:51622e6cca25a6a4b5c117d6f5117016a36d91fb56a2919cdb7ce11b8c47d5c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:91c09766e97e0dd7c5c34476ad10a03dc723034805e17639e74bdc32b2d073b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:69aa82e7c5e56137067abac2f8d31ba5abf36788a3bd1ebb7253d36894858a03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:10f7ff2b92d50c780418ec8d7d4b0ff3695d4eecda278eb00b374b93a613f88f